Saluts,
Une Attaque ???
Ça : /usr/share/ca-certificates/mozilla/Equifax_Secure_CA.crt.bak & /usr/share/ca-certificates/mozilla/Thawte_Premium_Server_CA.crt.bak c’est moi ce matin ! C’est normal !
Mais pour le reste ???
code# find /usr -type f -mtime -5 | less > rootkit_attaquant.txt
[/code]
[quote]:~$ cat rootkit_attaquant.txt
/usr/share/ca-certificates/mozilla/Equifax_Secure_CA.crt.bak
/usr/share/ca-certificates/mozilla/Thawte_Premium_Server_CA.crt.bak
/usr/share/doc/HTML/Games/index.html
/usr/share/doc/HTML/Games/Tools/index.html
/usr/share/doc/HTML/Programming/index.html
/usr/share/doc/HTML/Programming/C/index.html
/usr/share/doc/HTML/Programming/Python/index.html
/usr/share/doc/HTML/Video/index.html
/usr/share/doc/HTML/File management/index.html
/usr/share/doc/HTML/Help/Standards/index.html
/usr/share/doc/HTML/Help/index.html
/usr/share/doc/HTML/Help/Faq/index.html
/usr/share/doc/HTML/Help/Howto/index.html
/usr/share/doc/HTML/Debian/index.html
/usr/share/doc/HTML/Debian/Installation/index.html
/usr/share/doc/HTML/System/Administration/index.html
/usr/share/doc/HTML/System/Security/index.html
/usr/share/doc/HTML/System/index.html
/usr/share/doc/HTML/System/Monitoring/index.html
/usr/share/doc/HTML/System/Hardware/index.html
/usr/share/doc/HTML/Editors/index.html
/usr/share/doc/HTML/Web development/index.html
/usr/share/doc/HTML/index.html
/usr/share/doc/HTML/All/index.html
/usr/share/doc/HTML/Science/Mathematics/index.html
/usr/share/doc/HTML/Science/index.html
/usr/share/doc/HTML/Text/index.html
/usr/share/doc/HTML/Terminal emulators/index.html
/usr/share/doc/HTML/README
/usr/share/doc/HTML/Graphics/index.html
/usr/share/doc/HTML/Network/Web browsing/index.html
/usr/share/doc/HTML/Network/index.html
/usr/share/doc/HTML/Network/Communication/index.html
/usr/share/doc/HTML/Network/Monitoring/index.html
/usr/share/doc/HTML/Viewers/index.html
/usr/share/doc/HTML/Sound/index.html
/usr/share/doc/HTML/Emulators/index.html
/usr/share/icons/hicolor/icon-theme.cache
/usr/share/applications/mimeinfo.cache
:~$ [/quote]
Par anticipation …
code# mv /usr/share/doc/HTML /home/ …/…/…/…/le_dossier_qui_va_bien !!!
mv /usr/share/icons/hicolor/icon-theme.cache /home/ …/…/…/…/le_dossier_qui_va_bien !!!
mv /usr/share/applications/mimeinfo.cache /home/ …/…/…/…/le_dossier_qui_va_bien !!!
[/code]
code# find /usr -type f -mtime -5 | less > rootkit_attaquant_verif.txt
[/code]
cat rootkit_attaquant_verif.txt
/usr/share/ca-certificates/mozilla/Equifax_Secure_CA.crt.bak
/usr/share/ca-certificates/mozilla/Thawte_Premium_Server_CA.crt.bak
:~$ [/code]
[quote]rkhunter -c -sk
[ Rootkit Hunter version 1.3.6 ]
Checking rkhunter data files…
(…)
Checking system commands…
/usr/sbin/ifstatus [ Warning ]
…
Performing additional rootkit checks
…
Checking for possible rootkit strings [ Warning ]
…
Performing filesystem checks
Checking /dev for suspicious file types [ Warning ]
Checking for hidden files and directories [ Warning ]
System checks summary
File properties checks…
Files checked: 135
Suspect files: 1
Rootkit checks…
Rootkits checked : 248
Possible rootkits: 2
Rootkit names : Xzibit Rootkit, Xzibit Rootkit
Applications checks…
All checks skipped
The system checks took: 1 minute and 32 seconds
All results have been written to the log file (/var/log/rkhunter.log)
One or more warnings have been found while checking the system.
Please check the log file (/var/log/rkhunter.log)
[/quote]
A votre avis … ???
-edit-
à côté de la plaque …